CVE-2023-50671

In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write to an unexpected address.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:aertherwide:exiftags:1.01:*:*:*:*:*:*:*

History

18 Jan 2024, 18:54

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Aertherwide
Aertherwide exiftags
CWE CWE-787
CPE cpe:2.3:a:aertherwide:exiftags:1.01:*:*:*:*:*:*:*
References () https://blog.yulun.ac.cn/posts/2023/fuzzing-exiftags/ - () https://blog.yulun.ac.cn/posts/2023/fuzzing-exiftags/ - Exploit, Third Party Advisory
References () https://johnst.org/sw/exiftags/ - () https://johnst.org/sw/exiftags/ - Product

12 Jan 2024, 13:47

Type Values Removed Values Added
Summary
  • (es) En exiftags 1.01, nikon_prop1 en nikon.c tiene un desbordamiento de búfer en la región Heap de la memoria (escritura de tamaño 28) porque snprintf puede escribir en una dirección inesperada.

11 Jan 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-11 17:15

Updated : 2024-01-18 18:54


NVD link : CVE-2023-50671

Mitre link : CVE-2023-50671

CVE.ORG link : CVE-2023-50671


JSON object : View

Products Affected

aertherwide

  • exiftags
CWE
CWE-787

Out-of-bounds Write